Sr. Security Engineer, Product Security

6 Months ago • 8 Years + • Cyber Security

Job Summary

Job Description

The Sr. Security Engineer, Product Security will provide technical leadership to a team securing Xerox's digital platforms. Responsibilities include assessing applications for vulnerabilities, implementing secure SDLC processes, performing secure code reviews, developing security automation tools, defining security requirements, conducting security training, reporting on security metrics, researching industry trends, and acting as a security evangelist. This role requires strong application security expertise and collaboration skills.
Must have:
  • Assess applications for vulnerabilities
  • Implement secure SDLC processes
  • Secure code reviews/static analysis
  • Develop security automation tools
  • Threat modelling, security design reviews
  • Security training for development teams
  • Report on product security metrics
  • 8+ years cybersecurity experience, 5+ in product security
Good to have:
  • Java, .Net, C#, C, C++ experience
  • Prior software development experience

Job Details

About the job


About Xerox Holdings Corporation

For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power today’s workforce. From the office to industrial environments, our differentiated business solutions and financial services are designed to make every day work better for clients — no matter where that work is being done. Today, Xerox scientists and engineers are continuing our legacy of innovation with disruptive technologies in digital transformation, augmented reality, robotic process automation, additive manufacturing, Industrial Internet of Things and cleantech. Learn more at www.xerox.com and explore our commitment to diversity and inclusion.

Summary:

This position is part of the Xerox Cyber Security team that is responsible for driving security of Xerox digital platforms. The qualified candidate will provide technical leadership to a multidisciplinary product security team that is responsible for securing enterprise systems, applications, and products across a broad spectrum of technologies. The candidate must demonstrate a passion for application security and lead by example that fosters continued growth and technical expertise within the team.

Responsibilities include, but are not limited to:

  • Assess applications and products for security vulnerabilities and design flaws
  • Implement secure SDLC processes through effective collaboration
  • Manual and Automated Secure Code Review
  • Development of security automation tools
  • Develop and maintain secure coding practices and security engineering standards for the development team
  • Perform threat modelling, security design reviews of application or products and define security requirements as part of SDLC process
  • Security training for internal development teams
  • Track and report on product security metrics and communicate the security posture of products to stakeholders.
  • Research, analyze and report on security industry trends and products
  • Serve as a security evangelist for executive management and business stakeholders.

Knowledge and Skills Required:

  • Strong understanding of common vulnerabilities, attack vectors and corresponding mitigation techniques
  • Experience in performing secure code reviews/reviewing results of static analysis tools
  • In-depth understanding of secure coding practices and secure development life cycle principles.
  • Good understanding of SSDLC as well as development and integration of tools used as part of CI/CD process
  • Have good understanding of authentication and authorization standards and protocols (SAML, Oauth, LDAP etc.)
  • Strong exposure to popular application security standards including OWASP TOP 10, SANS TOP 25 etc.
  • Proficiency with at least one of the following programming languages desired: Java, .Net, C#, C, C++
  • Prior software development experience is a plus.
  • Strong interpersonal skills as well as excellent written and verbal communication skills
  • Uncompromising personal and professional integrity and ethics

Education and Experience Required:

  • B.S in computer science, information systems, engineering or related field.
  • Advanced degree preferred, i.e. MBA or MS
  • Over 8 years of experience in cybersecurity, with at least 5 years in product security
  • One or more Industry-standard security certifications (such as OSCP, OSWE, CWEE, OSED)

Similar Jobs

The Walt Disney Company - Senior Software Engineer, Data Reliability

The Walt Disney Company

Santa Monica, California, United States (On-Site)
1 Month ago
Airbyte - Engineering Talent Network

Airbyte

San Francisco, California, United States (On-Site)
1 Month ago
Capgemini - Java developer

Capgemini

Gurugram, Haryana, India (On-Site)
3 Weeks ago
PwC - Senior Associate _ Automation Tester_ Emerging  Technologies_ Advisory_ Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
8 Months ago
PwC - Senior Workday Integration Consultant

PwC

Warsaw, Masovian Voivodeship, Poland (Hybrid)
7 Months ago
bytedance - Cloud Security Architect

bytedance

Singapore (On-Site)
2 Months ago
Zazz - Cybersecurity Analyst

Zazz

(Remote)
3 Months ago
PwC - Cybersecurity Associate

PwC

Makati, Metro Manila, Philippines (On-Site)
8 Months ago
bytedance - Executive Protection Specialist

bytedance

Singapore (On-Site)
2 Months ago
PwC - Consultant expérimenté cybersécurité | CDI | H/F

PwC

Neuilly-sur-Seine, Île-de-France, France (On-Site)
8 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Qualcomm - Senior Engineer - Linux Stability

Qualcomm

Hyderabad, Telangana, India (On-Site)
2 Weeks ago
Games 24x7 - SDET-1 (Backend Tester)

Games 24x7

Bengaluru, Karnataka, India (On-Site)
3 Weeks ago
Marsh McLennan - Senior Applications Development Analyst

Marsh McLennan

Mexico City, Mexico (Hybrid)
2 Weeks ago
Demandbase - Principal Software Engineer

Demandbase

San Francisco, California, United States (Remote)
2 Weeks ago
bounteous - AEM Developer (FE)

bounteous

India (Remote)
3 Years ago
Epic Games - Senior Gameplay Systems Programmer, Fortnite

Epic Games

Canada (On-Site)
1 Month ago
Zscaler - Senior Software Development Engineer

Zscaler

Bengaluru, Karnataka, India (Hybrid)
4 Days ago
Google - Senior Software Engineer, RCS for Business

Google

Kraków, Lesser Poland Voivodeship, Poland (On-Site)
1 Month ago
bytedance - Site Reliability Engineer, Compute Platform

bytedance

San Jose, California, United States (On-Site)
6 Months ago
Ubisoft - Gen AI Programmer

Ubisoft

Pune, Maharashtra, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

bosh group india - S/4 HANA Public cloud FICO consultant

bosh group india

Bengaluru, Karnataka, India (On-Site)
2 Months ago
PowerSchool - Cloud Operations Engineer 1

PowerSchool

Bengaluru, Karnataka, India (On-Site)
7 Months ago
CGS Carrers - Test Automation Lead

CGS Carrers

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
luxsoft - Senior Project Manager with Scrum Master

luxsoft

Bengaluru, Karnataka, India (On-Site)
4 Days ago
Red panda games - Sofware Developer for mobile games

Red panda games

Bengaluru, Karnataka, India (Remote)
9 Months ago
NVIDIA - Senior Site Reliability Engineer - AI Research Clusters

NVIDIA

Hyderabad, Telangana, India (Hybrid)
1 Month ago
FICO - DevOps Engineering Enablement-Lead Engineer

FICO

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Gates Corporation - SPT Engineer

Gates Corporation

Chennai, Tamil Nadu, India (On-Site)
8 Months ago
Qualcomm - Sr Engineer- Graphics

Qualcomm

Hyderabad, Telangana, India (On-Site)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Smilegate - Security Threat and Incident Analysis

Smilegate

Seongnam-si, Gyeonggi-do, South Korea (On-Site)
2 Months ago
Magna International - Sr. Penetration Test Engineer

Magna International

Bengaluru, Karnataka, India (On-Site)
8 Months ago
OKX - Graduate Hire 2024/25 - SRE/Security Engineer

OKX

Hong Kong (On-Site)
7 Months ago
Ubisoft - Security Analyst

Ubisoft

Montreal, Quebec, Canada (On-Site)
1 Month ago
PwC - Application Security Manager

PwC

Makati, Metro Manila, Philippines (On-Site)
8 Months ago
bytedance - Research Scientist, Data Management and Security - Infrastructure System Lab

bytedance

San Jose, California, United States (On-Site)
1 Month ago
PwC - Salesforce Technical Lead (Manager)

PwC

Makati, Metro Manila, Philippines (Hybrid)
8 Months ago
Tencent - Security Operations - PUBG Mobile

Tencent

Shenzhen, Guangdong Province, China (On-Site)
3 Months ago
bytedance - Security Engineer (Penetration Tester) - Security Assurance

bytedance

Singapore (On-Site)
7 Months ago
Zazz - Cybersecurity Analyst

Zazz

(Remote)
3 Months ago

Get notifed when new similar jobs are uploaded